6.1
CVSSv3

CVE-2018-5479

Published: 15/01/2018 Updated: 05/02/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

FoxSash ImgHosting 1.5 (according to footer information) is vulnerable to XSS attacks. The affected function is its search engine via the search parameter to the default URI. Since there is an user/admin login interface, it's possible for malicious users to steal sessions of users and thus admin(s). By sending users an infected URL, code will be executed.

Vulnerable Product Search on Vulmon Subscribe to Product

foxsash imghosting 1.5

Exploits

# Exploit Title: ImgHosting Image Storage System 15 - Cross-Site-Scripting # Date: 12-01-2018 # Exploit Author: Dennis Veninga # Contact Author: dveninga [at] networking4allcom # Vendor Homepage: foxsashcom # Version: 15 # CVE-ID: CVE-2018-5479 ImgHosting – Image Storage System quick and easy image hosting without registration Service is i ...
ImgHosting version 15 suffers from a cross site scripting vulnerability ...